Soter Logo

Platform

WorkflowsAutomate safety tasks end-to-end
RecordsBrowse and manage structured safety records
Use CasesSee every way SoterAI can help
#BuildWithSoterConcept builds on the SoterAI platform

By Role

For EHSBuilt for safety & EHS professionals
For InsuranceScale loss control, underwriting & risk

By Industry

InsuranceConstructionManufacturingWarehousing & LogisticsHealthcareOil & GasRetail & Hospitality
Explore all use cases
Pricing

Resources

Case StudiesReal results from real customers
BlogInsights on AI-driven safety
WhitepapersResearch & thought leadership
IntegrationsConnect your existing tools
Help CenterDocumentation & support
Log InTalk to our team

SoterAI Browser Extension Privacy Policy

Last updated: 7 October 2026

SoterAI Browser Extension carries content you choose between pages, forms and chats. It is part of SoterAI, which is provided by Soter Analytics Inc. (United States), Soter Analytics Ltd (United Kingdom) and Soter Analytics Pty Ltd (Australia) ("Soter", "we", "us"). This policy covers the extension. Your SoterAI account itself is covered by the SoterAI privacy policy.

What is stored

When you press Copy, SoterAI Browser Extension captures the available readable page or conversation, labeled fields, table rows and source context such as the page title, URL, links and capture time. This includes contact addresses declared on visible page elements, even when the page displays only a name; those addresses are part of the copied source a Paste can send. It stores one payload inside your own browser's extension storage. A new copy replaces it; Discard removes it.

Copy makes no model request and sends nothing. The details it saves are the ones the page itself labels, read on your device; the full captured source is kept with them. Copy needs you to be signed in to SoterAI.

When data leaves your browser

Copy sends nothing. When you press Paste on a form, the extension first fills what the saved details settle on their own. If fields are left and you are signed in to SoterAI, Paste sends the copied source, the saved details and the destination page's and form's titles, section headings and field descriptions (labels, hints, nearby text, placeholders, field names and the choices a list offers) to SoterAI's gateway, which passes them through Vercel AI Gateway to the model provider to match those fields.

A long source is sent in up to five parts, each in its own request. The copied source is marked for the model provider's short-lived prompt cache, so a repeated request with the same source can reuse it; the zero-retention requirement below applies to those requests too. A request the gateway is too busy for is sent again after a wait of at most 5 seconds, up to twice. A request refused for another reason (other than sign-in, account access, size or a usage limit) while it carries the cache mark is sent once more without it. An embedded form on the page sends it again, and each Paste sends it again.

Paste writes on its own only values it traces to your copy or your saved details. A choice it cannot trace, or a tick, is shown as a suggestion and written only when you click it. Signed out, Paste fills from the saved details on your device and sends nothing. Inserting a saved copy into a chat does not call a model.

Every model request made by the extension sets providerOptions.gateway.zeroDataRetention: true. On Vercel's route, this restricts processing to providers eligible for zero data retention. If that route is refused, the extension does not retry with weaker retention. Model requests are made only as part of your Paste action.

Vercel's documented ZDR controls require an eligible plan and routing configuration. The extension and SoterAI's gateway request that policy; neither can independently inspect a provider's infrastructure.

SoterAI's gateway

The extension carries no model key. Paste's model requests go to SoterAI's gateway at aigw.ai.soter.com with your ai.soter.com sign-in attached. The gateway:

  • checks that sign-in with SoterAI's sign-in service, which returns your SoterAI user ID and account email, and refuses anonymous sessions and accounts without an email. To avoid a check on every request, it remembers the result in memory (your user ID and email for up to two minutes, a refused sign-in for up to 30 seconds), keyed by a hash of the sign-in token and never past the token's expiry;
  • replaces the request-level provider settings with zero data retention and prompt training disallowed, whatever the request asked for. Options on individual parts of the request, such as the prompt-cache mark on the copied source described above, are passed on unchanged;
  • forwards the request to Vercel AI Gateway with SoterAI's own key. Your sign-in token is not forwarded;
  • returns the answer. It does not store or log request or response content.

For each request the gateway logs the time, method, path, status, your SoterAI user ID, the tool name and the duration. It never logs headers, tokens or content. It counts requests per SoterAI user ID to enforce usage limits and keeps only the current day's counts. Like any web server, the gateway receives the IP address each request comes from, and uses it only to slow repeated failed sign-ins: when SoterAI's sign-in service refuses a sign-in, the gateway counts that failure against that address in memory. The gateway itself does not log the address or write it to disk. SoterAI's gateway keeps no copy of your payload.

Who receives your data

Data from the extension goes only to these parties, and only when you press Paste while signed in:

  • Soter, which runs SoterAI and SoterAI's gateway.
  • SoterAI's gateway at aigw.ai.soter.com, which receives Paste's requests and your sign-in, as described above.
  • SoterAI's sign-in service, which SoterAI's gateway asks to confirm your sign-in token. It is run for Soter by a provider listed in the SoterAI privacy policy's subprocessors.
  • Vercel AI Gateway (Vercel, Inc.), which receives the request from SoterAI's gateway and routes it to the model provider, with zero data retention and no prompt training required.
  • The model provider that runs the model matching your fields. The extension uses Anthropic's Claude Haiku 4.5, served by a provider Vercel AI Gateway selects among those eligible for zero data retention. If none is eligible, the request is refused.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use data from the extension only to provide Copy and Paste. We do not sell it, use it for advertising, or use it to determine creditworthiness or for lending.

What is excluded

Capture excludes regions hidden with standard controls (display: none, visibility: hidden, the hidden and aria-hidden attributes, and content-visibility) and authentication/payment credential controls, such as password, one-time-code and card-autocomplete inputs. Capture also leaves out screen-reader-only text and text placed far off the page. It still keeps text made transparent (opacity: 0, which pages use to fade sections in), text clipped by a scrolling box or covered by another element, and text coloured like its background; filled form fields and the labelled details can also keep screen-reader-only and off-page labels and values. That text is part of the copy and a signed-in Paste can send it. This is a check on controls and labels, not a blanket redaction of ordinary source text. Business identifiers and other information shown as content remain in the chosen copy.

Paste refuses an answer that quotes a credential, a card number or a Social Security number from the copy, or that would fill a field labelled for a secret, a card or bank number, an identity number or health details. A value quoted into a field that says where a payment goes (a payee, remit-to or bill-to box, a bank or account detail, or an address or email in a payment section) is only suggested, never filled.

Paste never fills password, one-time-code, payment-card, file-upload or hidden inputs, or fields covered by its identity/banking/date-of-birth restrictions. It never submits a form, sends a chat message, or overwrites an existing value.

Page access

Capture occurs when you press Copy. Paste inspects the destination fields or composer.

On chatgpt.com, chat.openai.com, claude.ai, ai.soter.com and dev-ai.soter.com, a small observer script runs inside the page from the moment it starts loading. It watches the responses to the site's own network requests and keeps, in memory only, the last few that look like a conversation (and up to three conversations on SoterAI's own chat), so Copy can save the chat you have open. It passes every response to the site unchanged, makes no requests of its own and stores nothing, and the extension asks it for what it holds only when you press Copy; its reply stays inside that page. What it holds is gone when the tab closes or reloads.

At installation, access is requested for those five sites only. The toolbar icon can enable the current page for that visit via Chrome's activeTab grant. Persistent access to another site is optional: the extension's settings page asks for it through Chrome's permission prompt, for one site, or for every site only if you choose that. Review or revoke access at chrome://extensions.

The cookies permission reads only ai.soter.com's cookies and uses only your SoterAI sign-in among them: to check that you are signed in, when the card opens, when you return to its tab or open a panel, and before Copy and before Paste asks for AI matching (only a yes or no reaches the card on the page), and to attach your sign-in to Paste's model requests to SoterAI's gateway. It uses only the sign-in's access token, never its refresh token, never reads another site's cookies, and never sets, changes or deletes a cookie. SoterAI Browser Extension does not request browsing-history access.

Accounts and diagnostics

SoterAI Browser Extension has no accounts of its own; it uses your existing SoterAI account. It has no advertising or analytics SDK. Capture diagnostics are written to the local developer console as outcome codes, methods and counts; they do not contain captured content. Paste's model requests are the extension's only network requests; websites you use still make their own requests independently.

Deleting your copy

Discard removes the saved payload from extension storage. Removing the extension removes its stored data and access to sites. Neither action removes content you already pasted into another application; that application controls its own copy.

Contact

Questions about this policy or the extension: support@soter.com

SoterAI

Virtual loss control that reduces injuries and claims

Solutions

SoterAI PlatformWorkflowsRecordsSoterCoachErgonomic Assessment

Resources

#BuildWithSoterUse CasesCase StudiesBlogIntegrationsHelp CenterPricing

Compare

Soter vs SafetyCultureSoter vs VelocityEHSSoter vs TuMekeSoter vs InseerSoter vs FurtherAI

Company

About Usinfo@soteranalytics.comSoterAI Trust CentreSoterAI Privacy PolicySoterAI Browser Extension Privacy PolicySoterCoach Privacy PolicyTerms of Use

© 2026 SoterAI. All rights reserved.